Avaliação de Ferramentas de Análise Estática de Código para Detecção de Vulnerabilidades
暂无分享,去创建一个
[1] Gary McGraw,et al. ITS4: a static vulnerability scanner for C and C++ code , 2000, Proceedings 16th Annual Computer Security Applications Conference (ACSAC'00).
[2] Ken Frazer,et al. Building secure software: how to avoid security problems the right way , 2002, SOEN.
[3] Gerard J. Holzmann,et al. UNO: Static Source Code Checking for User-Defined Properties 1 , 2002 .
[4] David A. Wagner,et al. Model Checking One Million Lines of C Code , 2004, NDSS.
[5] Wouter Joosen,et al. Code injection in C and C++: a survey of vulnerabilities and countermeasures , 2004 .
[6] Dominique Alessandri,et al. Attack-class-based analysis of intrusion detection systems , 2004 .
[7] Gary McGraw,et al. Software Penetration Testing , 2005, IEEE Secur. Priv..
[8] Alexander Ivanov Sotirov. AUTOMATIC VULNERABILITY DETECTION USING STATIC SOURCE CODE ANALYSIS , 2005 .
[9] Radu Rugina,et al. Memory Leak Analysis by Contradiction , 2006, SAS.
[10] George C. Necula,et al. Dependent Types for Low-Level Programming , 2007, ESOP.